A member of the SOC team is checking the dashboard provided by the Cisco Firepower Manager for further Isolation actions. According to NIST SP800-61, in which phase of incident response is this action?
According to NIST SP800-61, the incident response lifecycle consists of four phases: Preparation, Detection and Analysis, Containment, Eradication and Recovery, and Post-Incident Activity.
When a SOC team member checks the Cisco Firepower Manager dashboard for further isolation actions, they are working within the Eradication and Recovery phase.
This phase focuses on removing the threat from the environment and recovering affected systems to normal operations.
NIST SP800-61 Computer Security Incident Handling Guide
Incident Response Phases Explained
Role of SOC in Incident Response
Ryann
2 months agoAnnabelle
2 months agoVelda
1 months agoLazaro
1 months agoNieves
1 months agoJean
1 months agoRefugia
1 months agoJeffrey
2 months agoShizue
2 months agoClorinda
29 days agoWilda
1 months agoLuis
1 months agoCatherin
1 months agoElly
2 months agoAn
3 months agoLouisa
2 months agoRosann
2 months agoOna
2 months agoAllene
2 months agoSerita
2 months agoOzell
2 months agoBernadine
2 months agoAgustin
3 months agoTimothy
2 months agoSteffanie
2 months agoRebbecca
3 months agoAudra
3 months ago